Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by Jay - 27.01.2025
Last edited by cbay - 27.01.2025

FS#127 - Unrestricted File Upload on support Form

Summary:
A critical security vulnerability was identified in the file upload on the application. The flaw allows users to upload any file type, including executable files like .pdf, .php, and .exe, with invited members. This presents a significant risk, as malicious files could be uploaded and distributed, leading to potential exploitation and compromise of other systems.

Vulnerable url: https://admin.alwaysdata.com/support/add/

Closed by  cbay
27.01.2025 08:50
Reason for closing:  Invalid
Admin
cbay commented on 27.01.2025 08:50

Hello,

Uploaded files are not executed/interpreted on our servers. Our support team knows not to download and run any user-uploaded file.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing